21 May 2024

Dissecting Scattered Spider with Maltego

Maltego Team

Profiling requires conducting in-depth research on a threat actor ranging from the strategic, tactical, and operational levels. And multiple angles need to be covered. In this article, we delve into the intricate process of profiling the threat actor known as “Scattered Spider,” illustrating various techniques for data collection and analysis using Maltego


Who is Scattered Spider? 🔗︎

Scattered Spider is a threat actor group that has been widely known because of their consistency and creativity. They can be identified by multiple names established by the different industry players who analyzed them. Those aliases include Tarfraud, UNC3944, Scattered Swine, Storm-0875, LUCR-3, Octo Tempest, Roasted Oktapus, and Muddle Libra.

They have attacked hundreds of organizations worldwide since 2022, getting attention from the industry and other vendors such as CrowdStrike, Mandiant, Palo Alto Unit42, Trellix, SilentPush, and Group-IB. Their activities have even been featured on the CBS “60 Minutes” program.

Source: Infographic by CrowdStrike on victimology, shared via Adam Cyber on Twitter

Scattered Spider employs a variety of social engineering techniques, such as SMS phishing and impersonation in help desk calls. They also abuse compromised credentials to establish a foothold in their victims. This foothold is preserved and escalated through the use of living off the land (LOTL) techniques and legitimate remote access software. Additionally, they have a special predilection for abusing privileged cloud environment resources.

Source: Infographic by Mandiant on Threat Actor TTPs


The Scattered Spider group has conducted at least 3 remarkable campaigns so far:

  • Oktapus / March-July 2022: This campaign targeted employees of U.S.-based companies that use services from IAM leader Okta. The attackers created over a hundred unique domains that mimic these organizations, incorporating keywords such as “sso,” “vpn,” “okta,” “mfa,” and “help.”
  • C0027 / June-December 2022: This campaign focused on targeting mobile carriers, aiming to facilitate SIM-swapping attacks against victims.
  • Mid-2022-January 2023: This period saw the group targeting large outsourcing firms that serve high-value cryptocurrency institutions and individuals.

It’s important to note that in mid-2023, as reported by Unit42 from Palo Alto Networks, Scattered Spider began shifting their tactics to deploy ransomware in victim environments. This marks a significant change in the group’s monetization strategies, indicating an evolution in their behavioral patterns.

Scattered spider has effectively targeted victims using breached or stolen data, and they repeatedly return to the well to update their stolen dataset. Even after initial incident responses, they use this data to re-target previous victims. This group has consistently demonstrated a profound understanding of modern incident response processes, enabling them to persistently advance toward their goals and maintain access to victim networks, despite efforts by responders to remove them.

Early this year, the industry was surprised by the arrest of an individual named Michael Urban who uses the aliases “Sosa” and “King Bob” on alleged charges of SIM-swapping activities over different victims. As the cybercrime journalist, Brian Krebs, states, he was a top member of the broader cybercriminal community online known as “The Com,” wherein hackers boast loudly about high-profile exploits and hacks that almost invariably begin with social engineering — tricking people over the phone, email or SMS into giving away credentials that allow remote access to corporate internal networks. Sosa was also active in a particularly destructive group of accomplished criminal SIM swappers known as “Star Fraud.” Cyberscoop’s  AJ Vicens reported last year that individuals within Star Fraud were likely involved in the high-profile Caesars Entertainment and MGM Resorts extortion attacks.

Based on the reports and similar TTPs he employed, it is reasonable to assume that Mr. Urban might have close ties to the activities of the Scattered Spider group.

Source: A booking photo of Noah Michael Urban released by the Volusia County Sheriff(left) and Graphic by Amitai Cohen of Wiz used in krebsonsecurity article(right), depicting how Oktapus leveraged one victim to attack another.

Download the White Paper for Expert Tips! 🔗︎

In our whitepaper, we outline detailed techniques for data collection and analysis, specifying what and where to gather crucial Intelligence. We also present several effective methods for collecting threat intelligence using OSINT, threat intelligence communities, and private intelligence providers. The information is presented in a step-by-step format, making full use of Maltego’s seamless data integrations. The whitepaper enables readers to:

  • Identify relevant cyber threat intelligence data and sources.
  • Understand effective methods for collecting treat Intelligence from these sources.
  • Analyze the collected intelligence, enhance its integration, and enrich it with additional data sources.

Download the whitepaper to gather and analyze real-time intelligence with Maltego!

Download the resource

DE +49
Albania +355
Algeria +213
Andorra +376
Angola +244
Anguilla +1264
Antigua And Barbuda +1268
Argentina +54
Armenia +374
Aruba +297
Australia +61
Austria +43
Azerbaijan +994
Bahamas +1242
Bahrain +973
Bangladesh +880
Barbados +1246
Belarus +375
Belgium +32
Belize +501
Benin +229
Bermuda +1441
Bhutan +975
Bolivia +591
Bosnia and Herzegovina +387
Botswana +267
Brazil +55
Brunei Darussalam +673
Bulgaria +359
Burkina Faso +226
Burundi +257
Cambodia +855
Cameroon +237
Canada +1
Cape Verde +238
Cayman Islands +1345
Central African Republic +236
Chile +56
China +86
Cote d'Ivoire +225
Colombia +57
Comoros +269
Congo +242
Cook Islands +682
Costa Rica +506
Croatia +385
Cuba +53
Cyprus +90392
Czech Republic +42
Denmark +45
Djibouti +253
Dominica +1809
Dominican Republic +1809
Ecuador +593
Egypt +20
El Salvador +503
Equatorial Guinea +240
Eritrea +291
Estonia +372
Ethiopia +251
Falkland Islands (Malvinas) +500
Faroe Islands +298
Fiji +679
Finland +358
France +33
French Guiana +594
French Polynesia +689
Gabon +241
Gambia +220
Georgia +995
Germany +49
Ghana +233
Gibraltar +350
Greece +30
Greenland +299
Grenada +1473
Guadeloupe +590
Guam +671
Guatemala +502
Guinea +224
Guinea-Bissau +245
Guyana +592
Haiti +509
Honduras +504
Hong Kong +852
Hungary +36
Iceland +354
India +91
Indonesia +62
Iran, Islamic Republic of +98
Iraq +964
Ireland +353
Israel +972
Italy +39
Jamaica +1876
Japan +81
Jordan +962
Kazakhstan +7
Kenya +254
Kiribati +686
Korea, Democratic People's Republic of +850
Korea, Republic of +82
Kuwait +965
Kyrgyzstan +996
Lao People's Democratic Republic +856
Latvia +371
Lebanon +961
Lesotho +266
Liberia +231
Libyan Arab Jamahiriya +218
Liechtenstein +417
Lithuania +370
Luxembourg +352
Macao +853
Macedonia, the former Yugoslav Republic of +389
Madagascar +261
Malawi +265
Malaysia +60
Maldives +960
Mali +223
Malta +356
Marshall Islands +692
Martinique +596
Mauritania +222
Mauritius +230
Mayotte +269
Mexico +52
Micronesia, Federated States of +691
Moldova, Republic of +373
Monaco +377
Mongolia +976
Montserrat +1664
Morocco +212
Mozambique +258
Myanmar +95
Namibia +264
Nauru +674
Nepal +977
Netherlands +31
New Caledonia +687
New Zealand +64
Nicaragua +505
Niger +227
Nigeria +234
Niue +683
Norfolk Island +672
Northern Mariana Islands +670
Norway +47
Oman +968
Pakistan +92
Palau +680
Panama +507
Papua New Guinea +675
Paraguay +595
Peru +51
Philippines +63
Poland +48
Portugal +351
Puerto Rico +1787
Qatar +974
Reunion +262
Romania +40
Russian Federation +7
Rwanda +250
San Marino +378
Sao Tome and Principe +239
Saudi Arabia +966
Senegal +221
Serbia +381
Seychelles +248
Sierra Leone +232
Singapore +65
Slovakia +421
Slovenia +386
Solomon Islands +677
Somalia +252
South Africa +27
Spain +34
Sri Lanka +94
Saint Helena +290
Saint Kitts and Nevis +1869
Saint Lucia +1758
Sudan +249
Suriname +597
Swaziland +268
Sweden +46
Switzerland +41
Syrian Arab Republic +963
Taiwan +886
Tajikistan +7
Thailand +66
Togo +228
Tonga +676
Trinidad and Tobago +1868
Tunisia +216
Turkey +90
Turkmenistan +993
Turks and Caicos Islands +1649
Tuvalu +688
Uganda +256
United Kingdom +44
Ukraine +380
United Arab Emirates +971
Uruguay +598
United States +1
Uzbekistan +7
Vanuatu +678
Holy See (Vatican City State) +379
Venezuela +58
Viet Nam +84
Virgin Islands, British +84
Virgin Islands, U.S. +84
Wallis and Futuna +681
Yemen +967
Zambia +260
Zimbabwe +263

By clicking on "Access", you agree to the processing of the data you entered and you allow us to contact you for the purpose selected in the form. For further information, see our Data Privacy Policy.

Don’t forget to follow us on Twitter and LinkedIn and sign up for our email newsletter, so you don’t miss out on updates and news!

Happy investigating!

About the Authors 🔗︎

Carlos Fragoso

Carlos is the Principal Subject Matter Expert and Lead Instructor at Maltego with over 20 years of professional experience in information security: Incident response, digital forensics, threat intelligence, and threat hunting. A curious and passionate investigator working with big companies and LEAs to tackle cybercrime around the world (Europe, Middle East, LATAM) SANS Institute Instructor.

Acknowledgements:

We were excited to undertake this research to support our users and honor the InfoSec community, which tirelessly works to prevent cybercrimes. We recognize that many CTI teams face numerous requests and lack the time to manage all their data sources effectively. Our goal was to inspire them by demonstrating how Maltego can streamline this process and enhance various data integrations within one platform. Scattered Spider is just one of many threats, and we will continue to stand by your side to tackle them together.

Exciting developments are on the horizon—stay tuned for more updates!


Mathieu Gaucheler

Mathieu is a Subject Matter Expert at Maltego. His responsibilities include research-driven content development for blog posts, webinars, and talks. He started working in cybersecurity in Barcelona, focusing on malware analysis and sandbox development. He has previously presented his research at BotConf and RSA APJ.

Acknowledgements:

We trust that this article will not only provide insights into tracking threat actors across diverse datasets using Maltego, but also offer guidance on leveraging the fusion of these datasets to advance your investigations. By delving into the intricacies of combining various data sources, we aim to equip you with the knowledge needed to extend the scope and depth of your investigative efforts. It has been a privilege to play a role in this journey, and we remain committed to continually simplifying the process of analyzing threat intelligence.

By clicking on "Subscribe", you agree to the processing of the data you entered and you allow us to contact you for the purpose selected in the form. For further information, see our Data Privacy Policy.